Microsoft adds 'Tamper Protection' to Windows Defender
Microsoft will add a "tamper protection" feature to the built in antivirus tools in an upcoming Windows 10 update. It's designed to stop malware from switching off key security features in Microsoft Defender.
Initially the changes will be available for Microsoft Defender Advanced Threat Protection, which is a subscription service for businesses. However, Microsoft appears to have revealed it will later become available to home users of Windows 10. (Source: zdnet.com)
The idea is to prevent rogue apps from disabling some of the weapons in the Microsoft Defender arsenal, in turn making it far easier for malware to cause damage. Microsoft hasn't revealed exactly how it works, which is likely to avoid giving too much away to hackers.
Key Features Protected
The four main features that tamper protection will prevent apps from switching off are: real-time protection, which actively scans files rather than waiting to be manually run; cloud-delivered protection, which checks suspect files against a central database that's kept totally up-to-date with the latest detected threats; IOAV (IOffice Antivirus), which checks files a computer is trying to download; and behavior monitoring, which looks for suspicious activity by apps even if the app itself hasn't been recognized as a known threat.
Tamper protection will also prevent rogue apps from disabling Microsoft Defender completely and from deleting security updates.
Protection Activated By Default
Once tamper protection rolls out to home users, it can be switched on or off through the Windows Security app, which is the all-in-one settings menu for the security tools on a Windows PC. It will be on by default.
For business networks, the feature will only be controllable through the management console, which is the menu that system administrators use to control security across a network. It won't be accessible from individual computers, which Microsoft says is designed as an added layer of protection. The idea there is to not only protect against malware that has got onto a computer, but also against rogue employees who are intentionally trying to cause harm. (Source: microsoft.com)
What's Your Opinion?
Is this a welcome move from Microsoft? Should it have tackled this issue sooner? Do you think malware creators will figure out a way to get past this protection?
Most popular articles
- Which Processor is Better: Intel or AMD? - Explained
- How to Prevent Ransomware in 2018 - 10 Steps
- 5 Best Anti Ransomware Software Free
- How to Fix: Computer / Network Infected with Ransomware (10 Steps)
- How to Fix: Your Computer is Infected, Call This Number (Scam)
- Scammed by Informatico Experts? Here's What to Do
- Scammed by Smart PC Experts? Here's What to Do
- Scammed by Right PC Experts? Here's What to Do
- Scammed by PC / Web Network Experts? Here's What to Do
- How to Fix: Windows Update Won't Update
- Explained: Do I need a VPN? Are VPNs Safe for Online Banking?
- Explained: VPN vs Proxy; What's the Difference?
- Explained: Difference Between VPN Server and VPN (Service)
- Forgot Password? How to: Reset Any Password: Windows Vista, 7, 8, 10
- How to: Use a Firewall to Block Full Screen Ads on Android
- Explained: Absolute Best way to Limit Data on Android
- Explained: Difference Between Dark Web, Deep Net, Darknet and More
- Explained: If I Reset Windows 10 will it Remove Malware?
My name is Dennis Faas and I am a senior systems administrator and IT technical analyst specializing in cyber crimes (sextortion / blackmail / tech support scams) with over 30 years experience; I also run this website! If you need technical assistance , I can help. Click here to email me now; optionally, you can review my resume here. You can also read how I can fix your computer over the Internet (also includes user reviews).
We are BBB Accredited
We are BBB accredited (A+ rating), celebrating 21 years of excellence! Click to view our rating on the BBB.
Comments
Windows Defender tamper protection
I've already been burned by this. The latest update destroyed all performance until I figured out that Defender and Avast weren't getting along. All controls on Defender were greyed out or I got a "denied" when I tried to change one.
I'll be doing a little research to see what can be done to stifle its bothersome intrusions.
Possible Windows corruption
If you have parts of Windows that are not normally accessible (such as Windows Defender in this case), it may be because either your user account is corrupt or Windows is corrupt - FYI. This can happen if Windows is already corrupt and then you get a Windows Update that seems to 'break' things. Most likely you will have more strange issues like this in different parts of the OS. If you need help with this I can assist using remote support.